MiCA and crypto companies: who can continue operating in the EU from July

B2B analysis of the MiCA regime: who can operate in the EU from July 2026, CASP requirements, deadlines, ESMA registration and consequences of non-compliance.

On July 1, 2026, the transitional regime of Regulation (EU) 2023/1114—known as MiCA—ends across the European Union. For companies in the crypto-asset ecosystem, this date is not merely symbolic: it is the deadline after which any provider lacking authorization as a Crypto-Asset Service Provider (CASP) must cease providing services to clients within the European single market, as stipulated in Article 143 of the Regulation and the guidelines published by ESMA in April 2026. Until then, a significant portion of the sector has operated under legacy national registries that MiCA allowed for a limited period. That protection expires in just a few days.

What does MiCA cover and which companies does it affect?

MiCA is the first directly applicable European regulatory framework for the crypto-asset market. It came fully into force on December 30, 2024, for service providers, following the enactment of its provisions on stablecoins. —asset-linked tokens (ARTs) and electronic money tokens (EMTs)— They will begin to be applied in June 2024. The Regulation has a broad territorial scope: it applies not only to companies domiciled in the EU, but to any entity that offers services to users within the European Economic Area, regardless of where its headquarters are located.

The Regulation distinguishes three main categories of crypto assets —utility tokens, ART and EMT— and establishes a differentiated regime of obligations for issuers and service providers. With regard to providers, MiCA creates the role of the CASP and requires that any entity that professionally provides one or more of the services defined in the Regulation obtain authorization from the competent authority of its Member State before starting or continuing such activity.

Assets already regulated as financial instruments under MiFID IICentral bank digital currencies (CBDCs), single and non-fractional NFTs, and DeFi protocols without a legal entity controlling them are outside the scope, although centralized interfaces and services that interact with DeFi may be subject to it depending on their actual structure.

CASP services covered: what activities require authorization

The Regulation precisely lists the crypto-asset services whose professional provision requires CASP authorization. This list is the primary reference for any company that needs to determine whether its activity falls within the scope of the Regulation.

The services included are: custody and administration of crypto assets on behalf of clients; operation of a crypto asset trading platform; exchange of crypto assets for fiat funds or other crypto assets; execution of crypto asset orders on behalf of clients; placement of crypto assets with or without firm commitment; receipt and transmission of crypto asset orders on behalf of clients; management of crypto asset portfolios; and crypto asset advice. Each service entails a minimum capital requirement and governance requirements commensurate with the risk it generates, as detailed in the following section.

Traditional financial institutions—banks, investment firms, and asset managers—that wish to offer crypto-asset services do not need to obtain full CASP authorization if they already hold a license in the relevant category under MiFID II or other applicable directives: they can do so by notifying the competent authority in accordance with Article 60 of the Regulation. This was the mechanism used by BBVA, Openbank, and Cecabank in Spain, which notified the CNMV Their intention to provide crypto asset services without initiating the full CASP authorization process. Crypto-native companies without a prior financial license in the applicable category must complete the full process.

The transitional regime: from national registries to CASP authorization

MiCA, in its Article 143, provided a maximum transition period of 18 months for companies that were already legally providing crypto asset services under the national regulations in force before December 30, 2024. This mechanism sought to avoid an abrupt disruption of the market and give the sector enough time to complete the authorization procedures under the new European framework.

In Spain, previous regulations required providers of virtual currency-to-fiat currency exchange and electronic wallet custody services to be registered with the Bank of Spain, a registry established in May 2021 under Law 10/2010 on the prevention of money laundering. Entities registered by December 30, 2024, were covered by the transitional regime and could continue providing their services without CASP authorization until July 1, 2026, or until the CNMV (National Securities Market Commission) resolved their application—either granting or denying authorization.

It should be noted that the Bank of Spain's registry was abolished on December 30, 2024, although it remains available for informational purposes regarding registrations made before that date. Companies providing crypto-asset services not included in that registry—such as portfolio management or advisory services—were also able to take advantage of the transitional provisions, provided they were already doing so in accordance with national regulations.

It is worth highlighting a relevant change in position: in October 2023, the Spanish Government communicated to ESMA Spain's intention was to implement a 12-month transition period (until December 2025). However, the list of transition periods subsequently published by ESMA confirmed that Spain ultimately opted for the maximum 18-month period, aligning with the expiration date of July 1, 2026 (Cuatrecasas, December 2025). Companies operating under the transitional period thus gained an additional six months compared to the initial timeline set by the government.

Requirements to obtain CASP authorization

The CASP authorization process is substantially more demanding than prior registration with the Bank of Spain. The Regulation requires that the applicant be a legal entity with its registered office in an EU Member State and have at least one director residing within the EU. This requirement, seemingly technical in nature, effectively eliminates the possibility of serving European clients from an entity without a physical presence in the Union.

Capital requirements are tiered according to the type of service. Companies providing advisory services or order reception and transmission services must demonstrate a minimum capital of €50.000; those operating in the exchange of crypto assets, €125.000; and those operating trading platforms or providing custody services, €150.000. In all cases, equity must be equivalent to at least one-quarter of the fixed general expenses of the previous year, applying the greater of the two amounts (ILP Abogados, 2026).

The authorization dossier includes, in addition to proof of capital, detailed business plans, corporate governance structures, anti-money laundering and counter-terrorist financing (AML/CTF) policies, business continuity plans and cybersecurity policies compatible with DORA —the digital operational resilience regulation that applies to CASPs from January 1, 2026.

In Spain, the CNMV is the competent authority for supervising compliance with MiCA and for granting CASP authorizations. Authorization obtained in a single Member State acts as a European passport: once the entity is registered with ESMA, it can provide services in all 27 Member States without requiring additional authorization in each country. The ESMA registration process begins once the corporate incorporation or transformation formalities have been completed in accordance with the terms of the authorization received.

Current status: the ESMA registry overview as of June 2026

With three weeks remaining in the transition period, the European balance is considerably tighter than the industry anticipated at the start of the process. According to industry data, around 1.200 companies held some form of prior national registration in the European Union before the full implementation of MiCA. Of these, only about 210 have managed to convert that status into a full CASP license by June 2026, representing a conversion rate of approximately 17%. The remaining 83% face three possible scenarios: they missed the deadline, they are still in the process without a valid authorization, or they have quietly exited the market.

The geographical distribution of authorizations is markedly uneven. Germany accounts for more than a quarter of all MiCA licenses issued in the EU. Ten Member States had not issued any authorizations through their own CASP processes as of the date the data was available (June 2026).

However, these figures require a nuanced interpretation for the Spanish case: the CNMV has accumulated eight authorizations granted —including notifications from financial entities and the first full CASP license, granted to Bit2Me in July 2025— with more than twenty applications under active review (CBInsights, 2026). The CNMV keeps its public register updated, while ESMA publishes the European register at esma.europa.eu with weekly updates.

Of the entities authorized at the European level, only 14 hold a Class 3 license, the category that enables them to operate an exchange platform with custody of client crypto assets, according to data from CriptoNoticias (June 2026). The remaining entities operate under Class 1 or 2 licenses, which cover advisory, brokerage, or trading services without direct custody. For non-EU companies with a user base in Europe, the situation is even more critical: MiCA does not consider the location of the headquarters, but rather the location of the client. If an authorized subsidiary has not been established in a Member State, the company has been exposed to regulatory non-compliance since July 1, regardless of its size or time in the market.

Consequences of non-compliance and the role of supervisors

ESMA has been explicit in its public communications: there will be no intermediate status after the transition period expires on July 1, 2026. Any company that lacks a valid CASP authorization on that date—whether granted directly by the CNMV or through a European passport from another Member State—must cease providing its services in the European market, in accordance with the regulator's guidelines. An authorization pending decision does not, under any circumstances, equate to permission for continued operation, as ESMA expressly stated in its April 2026 communication.

The supervisory framework of the Regulation, set out in Title VII, empowers national competent authorities to adopt supervisory measures and impose administrative sanctions on entities that provide crypto-asset services without the required authorization. The measures contemplated include the temporary or permanent prohibition of activities, the publication of public warnings, and the imposition of financial penalties. For serious infringements, Article 111 of the Regulation establishes penalties that can reach the greater of the following thresholds: 15% of total annual turnover or twice the profit obtained from the infringement. Responsible natural persons may also be subject to individual measures depending on the provisions of each Member State's national transposition legislation.

For companies in the authorization process that do not receive a positive decision before July 1, ESMA has recommended that they have orderly closure plans ready for immediate implementation, with procedures for returning assets to customers and adequate communication with affected users. The European supervisor has also warned that applications submitted at the last minute will be subject to more rigorous scrutiny than those processed within the normal timeframes, which materially reduces the likelihood of an expedited positive decision.

Bit2Me: benchmark for MiCA compliance in Spain

Bit2Me, founded in Spain in 2014 and with over ten years of uninterrupted activity in the sector, was the first Spanish-speaking fintech company to obtain CASP authorization from the CNMV (Spanish National Securities Market Commission) under the MiCA (Microsoft Accounting and Accounting Framework) in July 2025. This authorization was obtained through the full suitability process with the national regulator—not through the notification procedure for pre-existing financial institutions—making it the first pure crypto platform to complete the entire authorization process in Spain. This milestone was covered by both specialized and general media outlets across Europe and confirmed that the CASP process is viable for native operators within the crypto ecosystem with a solid operational base.

Bit2Me's track record as a regulatory benchmark is supported by several verifiable elements: ten years without security incidents or loss of client funds, ISO 27001 cybersecurity certification, ISO 37001 and 37301 compliance certifications, and a business continuity plan compliant with ISO 22301. The platform operates under the supervision of the CNMV (Spanish National Securities Market Commission) with an integrated suite of services—Brokerage, Pro, Earn, Loan, and OTC—covering the main use cases of the corporate segment. For companies in the sector that manage their own authorization process or evaluate regulated infrastructure options in Spain, Bit2Me's accumulated experience as the first CASP (Customer Asset Service Provider) in the country represents a leading operational and regulatory benchmark in the local market.

Regulation as infrastructure for the crypto asset market in the EU

July 1, 2026, is not the end of a process, but the beginning of a new phase of maturity for the European market. MiCA has fulfilled its initial purpose of harmonizing the regulatory framework across the 27 Member States, replacing a patchwork of national registries with a single license and European passport system. The fragmentation that characterized the sector over the last decade has given way to an environment where CASP authorization is not an optional differentiator, but the minimum requirement for access to the single market.

For companies operating in the EU crypto ecosystem—or aspiring to do so—the roadmap from July onward is binary: obtain a valid CASP authorization, either directly or through a European passport, or cease providing services to European clients in accordance with ESMA guidelines. There is no third option. Entities that have completed the process now assume ongoing compliance obligations—reporting to the competent authority, DORA compliance, AML/CTF compliance, and reporting of operational incidents—which define the minimum standard for the regulated European market. For crypto companies operating in the EU, the question is no longer whether to comply with MiCA, but how to maintain that compliance sustainably as the Regulation and the ecosystem continue to evolve.


Investing in cryptocurrencies is not fully regulated, may not be suitable for retail investors due to its high volatility, and carries the risk of losing all invested funds. It is important to read and understand the risks of this investment, which are explained in detail at: https://up.bit2me.com/legalbit2me

Bit2Me operates as a Crypto Asset Service Provider authorized by the Spanish National Securities Market Commission (CNMV) under Regulation (EU) 2023/1114 (MiCA). BITCOINFORME, PSC, SL